Fortinet has confirmed active exploitation of critical FortiCloud single sign-on (SSO) authentication bypass vulnerabilities affecting its enterprise security products.
The company disclosed that threat actors are exploiting these vulnerabilities to gain unauthorized administrative access to compromised devices, creating significant risk for organizations relying on Fortinet infrastructure.
Vulnerability Overview
In December 2025, Fortinet identified two FortiCloud SSO bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) during an internal code audit.
These flaws allowed unauthenticated attackers to bypass SSO authentication through crafted SAML requests sent to FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager devices when FortiCloud SSO was enabled.
| CVE ID | CVSS Score | Affected Products | Attack Vector | Status |
|---|---|---|---|---|
| CVE-2025-59718 | 9.8 (Critical) | FortiOS, FortiWeb, FortiProxy, FortiSwitch Manager | Network/SAML Bypass | Active Exploitation |
| CVE-2025-59719 | 9.8 (Critical) | FortiOS, FortiWeb, FortiProxy, FortiSwitch Manager | Network/SAML Bypass | Active Exploitation |
Fortinet recently identified that threat actors are actively exploiting these vulnerabilities in real-world attacks.
The company observed unexpected login activity on customer devices resembling previous SSO bypass attempts.
However, the discovery of successful exploits against fully patched systems indicates a new attack vector beyond the originally disclosed vulnerabilities.
Security teams should monitor for the following IOCs associated with active exploitation:
Compromised User Accounts:
- cloud-noc@mail.io
- cloud-init@mail.io
Source IP Addresses:
- 104.28.244.115
- 104.28.212.114
- 37.1.209.19 (third-party observed)
- 217.119.139.50 (third-party observed)
Malicious Admin Accounts Created:
- audit
- backup
- itadmin
- secadmin
- support
Post-compromise, threat actors create local administrative accounts for persistence. Fortinet’s analysis reveals that attackers establish these accounts immediately after gaining SSO access, enabling continued access even if SSO credentials are disabled.
Organizations should audit all administrator accounts for unexpected entries created during suspicious timeframes.
Fortinet recommends immediate implementation of the following controls:
Restrict Administrative Access: Apply local-in policies to limit administrative interface access to trusted IP ranges only, preventing internet-exposed management ports.
Disable FortiCloud SSO: As a temporary workaround, disable the FortiCloud SSO feature via System Settings or CLI command set admin-forticloud-sso-login disable.
Monitor and Update: Organizations should regularly monitor the Fortinet PSIRT page for patch availability and register for security update notifications through the Fortinet Community.
If IOCs are discovered on compromised devices, Fortinet recommends treating the system as fully compromised and executing the following remediation steps:
- Update to the latest firmware version (7.6 recommended)
- Restore configuration from a known-clean backup
- Rotate all administrative credentials and connected LDAP/AD accounts
- Conduct a thorough audit of VPN configurations and user accounts
Fortinet is actively developing a permanent patch to address this new attack vector. An updated advisory will be released once the fix scope and deployment timeline are finalized.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
%20(1).webp?fit=1600,900&ssl=1)


